Comment 3 for bug 1978497

Revision history for this message
Jeremy Stanley (fungi) wrote :

Since this report concerns a possible security risk, an incomplete
security advisory task has been added while the core security
reviewers for the affected project or projects confirm the bug and
discuss the scope of any vulnerability along with potential
solutions.

Although the OpenStack Vulnerability Management Team doesn't
officially oversee[*] reports for the neutron-fwaas repository,
I've gone ahead and triaged this for now as if we would. That
said, I don't see a compelling reason to hold the discussion of
the presumed defect in private. Based on the comments above, I
don't think the described behavior becoming public knowledge
would put anyone's deployments at risk (if anything, it may help
some users by reminding them to double-check the composition of
their firewall rules).

[*] https://security.openstack.org/repos-overseen.html